| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, allowing unauthenticated attackers to harvest reviewers' email addresses and other non-public review content. |
| The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new term, allowing users with contributor-level access and above to create publicly visible terms in any taxonomy registered on the site. |
| In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. After a connection closes, a later connection that reuses the same file descriptor and message ID can receive the earlier authentication result. A remote attacker who can reach ldapd can complete a Bind as another identity. A missing connection can also cause a NULL pointer dereference. (ldapd is not enabled by default.) |
| Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. |
| Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. |
| In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree. |
| Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. |
| Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally. |
| Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. |
| SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API
endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows
remote attackers to execute arbitrary SQL commands via the id parameter. |
| Exposed Dangerous Method or Function in the
/WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote
authenticated users to execute arbitrary SQL commands via the sql parameter. |
| Unrestricted Upload of File with Dangerous Type in the
/WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version
before 2023/03/24 allows remote authenticated users to execute arbitrary
system commands via a malicious file. |
| Improper Limitation of a Pathname to a Restricted
Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp
API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote
authenticated users to write files to arbitrary locations outside the intended
upload directory via the path parameter. |
| A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions. |
| A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions. |
| Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.
This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07. |
| A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect. |
| Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of authentication and input validation, the request is processed successfully, allowing an attacker to write and execute arbitrary PHP code, resulting in remote code execution (RCE).
This issue was fixed in version 2.3.9. |
| Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse.
This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2. |